Sign inSign up
Node.js

dhi.io/node

Node.js 26.x / Socket Firewall (sfw, dev)

CIS
linux/amd64
alpine 3.24
Tags:

26-alpine-sfw-dev, 26-alpine3.24-sfw-dev, 26.10-alpine-sfw-dev, 26.10-alpine3.24-sfw-dev, 26.10.0-alpine-sfw-dev, 26.10.0-alpine3.24-sfw-dev

Index digest:

sha256:a52bc7e457bff242f71432650cf12189368659bca785eef466ff2dd008f7f614

Manifest digest:

sha256:e91d6f2a1c9a3cb8d7fef943543f5f60f8ac0193c9842ef83fd744ba4414be29

Size

87.98 MB

Last pushed

22 hours ago

Vulnerabilities

0
3
6
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:26-alpine-sfw-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:26-alpine-sfw-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:c0d95bd2ce498e40941901e56f738c469eaadf3b4593c650efe73f7164739227
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:3d18d0d249535d02e77d31de606b01effed1d957ed17bcf9f179659060872ff0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:5c59af1d2c256c95718a24cba9fb332ab6764e89efc03dbd1d6fbe7e68568181
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:0a02c78242266c753815f9e87a6f9ef0118cbf4fc3bb1196476a6ce290c3c59c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:454cddb5e10b8652253eaa31b87407354c3c047d13ec8bb101cd0b3ff6d58848
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:6c72ea480e06575e4aa3c75057f209a83d3de26003a95ad67c4459625e5bcf7f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:3923067ccc3d0f2861bfb882d7bf73e8262ca41d4addf4a3dba3eefd815ac8a0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:01ec527032e1e845fdf7b4b3edebc2ff43b0259b5ef75a82e0381b3bc8cd56be
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:25aa16df2a945bffac20037e6861d415b146981b28e316d63948b89115a6447d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:474e51565394a2939ffb8e197e565a7a08ee7876e53f052562451d5046f9f4a7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:e78cd0a5891d8e038c2c422dd33c4bf3cff9fabb2c3e1b4aa10148c02b58340a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:892b050fbc48e9190968ff4d9769a4516f00bed68b3c01f07b804c108daab085
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:6b8a57fd4e2af014f601dba0a42e15ead2640cbc4d85fe0d333f42be30a34e53
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:05094b1228406cc7c60b8b01833d40df24a16ea8d0765939b3efb3f7c2a26746